There are definitely many footguns with managing a VPS but I think the threshold to get vaguely competent with a VPS is not really that far off with getting familiar with the average cloud platform - which comes with its own dangers, like the near-total inability to put an upward cap on fees that that person found out with Netlify recently.
Having a $5 VPS and knowing it's never going to cost your more than $5 might balance out a lot of things on the other side for a lot of people.
(And, as a bonus, it comes with the benefit of having a better idea of what is going on on the actual computer which is running your code.)
Platforms like https://coolify.io/ (which I have not tried, but looks interesting) seem to give you some of the abstractions that you get in cloud platforms to save you having to mess with too much low level stuff and become an expert in a billion separate systems.
If you have Debian with automatic updates that does most of the heavy lifting for you. The hardest problem I have is resisting the temptation to just install everything, because the cost to do it is capped at my VPS monthly fee.
So yep, it comes with a lot of assumptions. But so does everything!
IMO vps was easy before and even easier now to manage.
(Aside: you shouldn't really be using SSH keys to begin with at anything but a small scale. SSH certificates are much more flexible)
2. Often there would be a cPanel plugin/extension/app/config value (if the hoster enabled it for you) that would just do for you what you needed.
The content & config are pushed by rsync/ssh from a git repo, so there's no need for backups. I can recreate a server in half an hour. I guess I lose the webserver logs, but I rarely look at them so I don't care.
A single server has plenty of bandwidth for a personal site, so there's only one EC2 instance and no secure network is needed. If I need more bandwidth, I'll use a load balancer but there's no need for secure connections between the load balancer & web servers because what's the eavesdropping threat model for a public content site?
Let's Encrypt seems to deal with https key rotation without manual intervention.
The cloud servers just have the usual ~cloud/.ssh/authorized_keys login setup, and I guess I rotate them every time a stronger crypto is recommended, which is 4ish times in 30 years.
Still I can think of a corporate blog, and you have employees come and go then it became a problem even for a small website. Otherwise an angry admin can deface your website and damage your reputation.
All other things like secure net won’t apply for a small website, of course.
- you add your ssh public key to the hosting provider, so any new VM will have it automatically
- you use the snapshot service of your hosting provider for backups. If you have a database, run a cronjob that dumps it so it's in the snapshots as well. Alternatively use any backup tool to backup files to somewhere else
- you do not need a separate network for simple use cases. Just encrypt traffic if you have multiple servers, odds are you only have one here anyway.
* You don't have to rotate what doesn't get out. Limit ingress to relevant IPs reduces this surface area a lot.
* SCP to a system built for storage. Not really essential for many systems - system logs are fine.
* Every VPS provider comes with a backup check box.
* Tailscale is really simple.is this harder than dealing with cloud 'platforms' and their ever-changing UIs, APIs, SDKs?
It's probably one less click to get a droplet turned up on Digital Ocean, and then you have to configure nginx or caddy (which is like five minutes if you've done it before, 30 if you haven't). Probably worth doing if it's your livelihood and you're afraid of Cloudflare disappearing, but if it's just a mess around... eh.
add your config, use chatgpt if you want, save `nginx -s reload` and bam! you're good to go, practically forever.
Badly.
I'm a mediocre Linux admin, at best. The current environment is so dangerous, these days, that it's worth your life, to have your essential services run by a mediocre admin; even if I can convince myself that I'm the best (spoiler: I'm not).
I'll generally run shared hosting, or managed servers.
I need the whole enchilada: DB, Web Server, Dynamic Languages, etc. Also, for a shipping, production application, with hundreds of users; where privacy and security are of paramount importance.
It's easy, sure. It's easy to create an insecure server, that can be pwned. I know of which I speak. I have done just that.
"A man who holds a cat by the tail, learns a lesson he can learn in no other way."
- Mark Twain
Use private keys. Use a firewall (ufw is really simple) and only expose your reverse proxy (e.g nginx or haproxy). Use docker to run your crap.
Any software engineer should be well capable of setting up a secure server. It really is simple.
The whole process takes maybe 30-60 minutes to setup for someone completely new and following guides.
Render's is simple, true, you just pay $300 for 1TB of bandwidth.
It's crazy how much Merchants of Complexity fooled devs into thinking that running your own server is complicated and you need to pay 1000x to save few minutes of your time.
I get that, a lot. It's the "No True Scotsman" of tech. This is also used as a way of validating college-style leetcode.
Let me introduce you to my GH Activity Graph[0]. See all that green? That's pretty much all coding in Swift; mostly in shipping apps and whatnot. There's a bit of PHP, for server-side stuff, but I like to spend a lot of time, coding frontend app stuff.
Every minute I spend, being a Linux admin, is a minute that I don't spend on executable code. I know that there's a number of folks, hereabout, that can code circles, around me, in Swift, and a few more, that can code circles around me, in PHP, but pretty much all of you, can run circles around me, in Linux admin. I'm not especially interested in competing, there; especially since a number of you are likely the folks that would Do Bad Things to my server, given an opening.
You don't have to be a linux admin to be able to setup a properly secure server, nowadays it's quite trivial. I bet you, that if you tried, you would be able to do so in less than an hour (at a relaxed pace).
We get lied to about the complexity of hosting by the cloud. I was able to host forums and game servers on VPSes when i was a young teenager, and I'm not technically gifted, it just wasn't complicated at all.
I tend to like shipping stuff, which means taking Responsibility for its operation, maintenance and security.
That often means a lot of "not fun." My servers are working servers. They have data and capabilities that are important to a lot of "not-Chris" people. It's my job to make sure that they get what they are [not] paying for (I write free stuff). That can be a bit stressful, at times; especially when some bad actor is making life miserable for me. I'd much rather that be someone else's problem, where I can write an email that says "Make it so, Numbah One!", instead of spending two days, wrestling with config files, and CLIs.
People are getting hacked a lot because of this, and docker doesn't seem to care all that much.
Firewalls are made for two things:
- packets alteration (iptable table mangle)
- applying filtering on behalf of a badly configured OS
So, if your case and if you want to prevent remote access to your database, you have a bad way: create a firewall rule to drop connections to tcp/3306And you have a good way: configure your sql to bind to ::1
The firewall way requires two configuration (hence: complexity) and hide your intent : the mysql say : "I accept connections from everybody", and then the firewall say "I deny all connections".
While the good way is clear and sane : one component who say : "I only accept connections from localhost"
I guess you gain some security, when you don't have to worry about some things. But you also lose some security, because of the added complexity.
sure it still needs work but much much less everyday
What a silly quote. “No other way” except all the other ones. Everyone watching the man and the cat will learn the same lesson. Everyone who hears the story will learn the same lesson.
I never held a cat by the tail, nor have i ever seen anyone foolish enough to attempt it, yet I am certain I know what happens next.
People FAFO when they should know better all the time.
I think the person in the original article was, at least for the sound file.
> I need the whole enchilada: DB, Web Server, Dynamic Languages, etc. Also, for a shipping, production application, with hundreds of users; where privacy and security are of paramount importance.
It seems quite simple to me, you either learn security, or pay for the expertise of someone that has. You need to decide whether it's worth your time.
I would suggest one thing, though - even with the likes of <big cloud>, they will only provide security in limited cases, i.e. DDoS. Nobody at <big cloud> is going to make sure your application logic works correctly - they clearly won't even make sure you use their resources within sensible bounds.